External risk intelligence

Oracle Identity Manager Remote Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60329

Oracle Identity Manager is an enterprise identity and access management solution. While such systems are often protected by perimeter controls, they are frequently deployed as internet-facing or externally reachable portals to support remote access, federation, and identity management functions, making them a common target for network-accessible exploitation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Identity Manager, a product within Oracle Fusion Middleware. This issue is easily exploitable by unauthenticated attackers over the network, potentially leading to a complete takeover of the Oracle Identity Manager system. The severity score indicates significant impacts on confidentiality, integrity, and availability.

  • Unauthenticated network attackers can take over Oracle Identity Manager.
  • This affects critical identity and access management systems.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can target Oracle Identity Manager over the network, using protocols like T3 or IIOP. This access allows them to interact with the OIM Legacy UI component, leading to the complete compromise of the identity management system.

  • Network access required.
  • Vulnerable OIM Legacy UI component.
  • Identity Manager takeover possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain complete control of Oracle Identity Manager when accessible over a network. This could expose sensitive identity and access management data and disrupt critical operations.

  • Identity and access management data.
  • Network access via T3, IIOP.
  • Takeover of Oracle Identity Manager.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle Identity Manager is likely managed by a dedicated Identity and Access Management (IAM) or platform engineering team, with support from infrastructure and security operations. The first step is to pinpoint all instances of Oracle Identity Manager within the environment, assess their network exposure and business criticality, and then confirm the accountable owner to prioritize remediation efforts.

  • IAM or Platform Engineering owns remediation.
  • Verify Oracle Identity Manager network exposure.
  • Plan remediation based on criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Identity Manager and its OIM Legacy UI component?

Oracle Identity Manager is an enterprise software solution used by organizations to automate and manage user identities, access rights, and security roles. It serves as a centralized platform for controlling who can access specific resources. The OIM Legacy UI component is a specific part of this software used for managing user interfaces and administrative tasks. This vulnerability specifically impacts the OIM Legacy UI in versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware.

What does this vulnerability mean for Oracle Identity Manager?

This security issue allows an attacker to gain full, unauthorized control over the Oracle Identity Manager system. While the specific underlying weakness class is not categorized, the vulnerability represents a significant flaw that bypasses typical security barriers. Because it grants a complete takeover, an attacker could potentially access sensitive identity data, modify permissions, or disrupt critical authentication operations without needing any prior system credentials or user interaction.

How does an attacker trigger this CVE-2026-60329 vulnerability?

An attacker triggers this vulnerability by sending malicious network traffic directly to the Oracle Identity Manager system. The attack relies on the use of T3 or IIOP protocols, which are common methods for communication in Java-based enterprise environments. It is important to note that the vulnerability cannot be triggered through local or console access alone; it requires specific network connectivity to reach the affected service and interact with the vulnerable OIM Legacy UI component.

Is my Oracle Identity Manager instance at risk?

Your risk depends on your network architecture. Halo Surface Signal notes that while identity systems are often behind perimeter defenses, they are frequently exposed as internet-facing portals to facilitate remote access or federation. If your instance can be reached via network protocols like T3 or IIOP from outside your core infrastructure—or even from untrusted segments within your internal network—it is considered reachable and should be treated as a priority for review.

What should I do if I run Oracle Identity Manager?

Start by identifying all instances of Oracle Identity Manager currently running in your environment. Confirm the specific versions in use to see if they match the affected 12.2.1.4.0 or 14.1.2.1.0 releases. Once identified, evaluate their network accessibility and business importance to determine how quickly you need to act. Collaborate with your Identity and Access Management or platform engineering teams to track down these systems and prepare for necessary security updates or configuration changes.

References